Simplest way to get HTTPS in front of a few home services?
Caddy, because certificate handling is the default rather than a plugin:
archive.example.com {
reverse_proxy 127.0.0.1:8080
encode zstd gzip
}
That is the entire configuration, certificates included. The equivalent nginx setup is four times longer and needs a separate renewal timer that fails silently.
Is port forwarding to a home server a bad idea?
It is a decision, not a mistake, but the safe version has three parts: no admin interfaces exposed, automatic updates on whatever is exposed, and a separate VLAN so a compromise does not reach the rest of the house. A VPN or a tunnel avoids all three questions, at the cost of client setup.
What is the minimum backup for a home server?
The data volumes and the compose files, nothing else. Containers are rebuildable; the database and the uploads are not. A nightly restic snapshot to a second machine plus a weekly copy offsite covers the realistic failure modes: disk death, deletion, and theft.
How do I know when it stops being worth it?
When you stop noticing it. If it has not surfaced a problem in six months, it is either solved or it was never the bottleneck you thought.
